Privacy Policy
Effective 29 August 2026
LotHook is used by towing operators and property managers to run parking permits. Most of the personal information in the system belongs to residents of the properties our customers service — we hold it on our customer's behalf, not for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train anything.
1Who we are
LotHook (the "Service") is operated by Innovations App Lab LLC, a Texas limited liability company. Reach us at Matthew.Maldonado@innovationsapplab.com or (346) 390-8060. Our mailing address for legal notices is available on request at that email address, and we will provide it within one business day.
This notice covers the LotHook web application, the public LotHook website, and the transactional email we send. It is the notice required by Tex. Bus. & Com. Code §541.102, and we have written it to meet that section whether or not the statute currently reaches a company our size.
2Controller and processor — this distinction decides everything below
When a towing company, HOA or management company (the "Customer") uses LotHook, the Customer decides which residents go into the system, why, and for how long. In the language of Tex. Bus. & Com. Code §541.001, the Customer is the controller of that information and we are a processor acting under a contract with them.
We are the controller for a narrower set: the accounts of staff who sign in, our billing records, the operational and security logs we keep to run the Service, and the records of who accepted which version of our agreements.
The practical consequence is in section 9. A resident asking us to delete their records is asking us to act on data that belongs, in law, to their property's account — so we route the request rather than deciding it alone. A staff user asking the same question is asking about data we control, and we answer directly.
3Categories of personal data we process
This is the disclosure required by §541.102(a)(1). It is written by category, as the statute asks, with the actual field names behind each so it can be checked.
Identifiers and contact information
Name, email address, and — only where a resident chooses to give one on a permit request — telephone number. For staff, the organization and role they hold and the properties they are assigned to.
Account credentials
Passwords are handled entirely by our authentication provider and stored only as salted hashes. We never receive, see, or store a password in readable form.
Vehicle information
Licence plate, plate state, make, model, colour and model year, and the unit a vehicle is registered against.
Permit and enforcement records
Permits with their issue and expiry times, whether a permit was issued by a resident or by staff, and any note the issuer attached. Permit requests and their review decisions.
Plate check records
Every licence plate check is logged: the plate searched, who searched it, the time, the property, the verdict returned, and a frozen copy of the result. This log exists so a disputed tow can be reconstructed months later, which is a benefit to the vehicle owner at least as much as to the operator.
Tow records
The plate and vehicle description, the reason recorded, the destination, the time, who recorded it, photographs uploaded as evidence, a frozen copy of what the permit check returned at that moment, and the geographic coordinates of the recording device.
Enquiries and demo requests
If you ask us for a demo we collect your name, your company, your role and the number of properties you service if you tell us, your work email address, your telephone number if you give one, whatever you write in the message box, and which page on our site you clicked through from.
We use it to reply to you. We do not add you to a marketing list, we do not sell it, and we do not pass it to anyone. It arrives as an email in our inbox rather than as a row in the product's database, because a table of prospects' names and phone numbers is a liability with no reader.
Sensitive personal data
We process one category of sensitive personal data, and we want to be direct about it. Tex. Bus. & Com. Code §541.001(29) defines sensitive data to include *precise geolocation data*, which §541.001(21) in turn defines as information that directly identifies the specific location of an individual within a radius of 1,750 feet. When an operator records a tow, the application captures the coordinates of the operator's own device at that moment, together with a measure of how accurate the fix was.
Three things narrow it, and all three are true of the code as built:
- The coordinates are of the operator's device, not of a resident or a resident's home.
- They are captured only at the instant a tow is recorded. There is no background location collection, no tracking of a device between events, and no location history.
- They exist to answer one question — was the vehicle where the operator says it was — which is the question in dispute in almost every complaint about a tow.
We do not process any other category of sensitive data. We do not collect racial or ethnic origin, religious belief, health information, sexual orientation, citizenship or immigration status, or genetic data.
Biometric identifiers — we process none
Tow photographs are photographs of vehicles. They may incidentally include a person who was standing nearby. Nothing in the Service computes a biometric identifier: we do not perform facial recognition, we do not extract face geometry, and we do not run automated plate recognition. Tex. Bus. & Com. Code ch. 503 turns on the *capture of a biometric identifier for a commercial purpose*, and we do not capture one.
If that ever changes, this section changes before the feature ships, and consent would be obtained separately rather than buried in this notice.
Technical and security information
Server and application logs, including IP address, timestamps and error diagnostics; rate-limiting counters, which store a salted hash of the subject rather than the raw identifier; and records of failed unit-code attempts.
We deliberately do not write resident names, licence plates or contact details into application logs.
Children
The Service is not directed at children and we do not knowingly collect personal information from anyone under 18. We do not operate a child-directed service under the Children's Online Privacy Protection Act, and we do not knowingly permit residents under 18 to hold accounts. If you believe a child has given us information, email us and we will delete it.
4Why we process it
The disclosure required by §541.102(a)(2), by purpose:
- To run the Service — issuing, checking, renewing and revoking permits; enrolling residents; managing properties and units.
- To create a record that survives an argument — plate check logs, tow records and their photographs exist so that a tow can be reconstructed by either side.
- To authenticate and authorize — deciding who may sign in and what they may see.
- To send transactional email — account confirmation, password reset, permit expiry warnings. These are not marketing and you cannot unsubscribe from the ones the Service depends on, though you can close your account.
- To secure the Service — rate limiting, lockouts, abuse investigation.
- To answer an enquiry — if you ask us for a demo, to reply to you about it.
- To bill our customers and keep our own business records.
- To establish, exercise or defend legal claims, our customers' as well as our own.
- To meet legal obligations.
We do not process personal data for a purpose that is neither reasonably necessary to, nor compatible with, the purposes disclosed here, which is the limit §541.101(b)(1) sets.
What we do not do
WE DO NOT SELL PERSONAL DATA. WE DO NOT SHARE PERSONAL DATA FOR TARGETED OR CROSS-CONTEXT BEHAVIOURAL ADVERTISING. WE DO NOT USE PERSONAL DATA FOR PROFILING THAT PRODUCES LEGAL OR SIMILARLY SIGNIFICANT EFFECTS. WE DO NOT USE CUSTOMER OR RESIDENT DATA TO TRAIN MACHINE LEARNING MODELS. WE RUN NO ADVERTISING ON THE SERVICE.
Because we do none of these things, there is no opt-out to offer for them: the disclosure and opt-out duties in §541.103 fall on controllers who sell personal data or process it for targeted advertising, and we do neither. If that ever changes we will say so here, give notice before it takes effect, and build the opt-out before we build the feature.
5Categories of personal data we share, and with whom
The disclosures required by §541.102(a)(4) and (a)(5).
We share personal data with four categories of recipient:
- Infrastructure and communications vendors engaged by us, listed by name below, who process data only on our documented instructions and may not use it for their own purposes.
- The Customer whose account the data sits under, and that Customer's authorised staff. This is not incidental — it is the point of the Service.
- Professional advisers, meaning our lawyers, accountants and insurers, where necessary and under a duty of confidence.
- Public authorities and parties to a legal claim, where we are legally required to disclose, or where disclosure is necessary to establish or defend a claim, or to protect someone's safety.
Our vendors are few enough to name rather than describe:
- Supabase — the database, authentication, and the private storage bucket holding tow photographs. Hosted on Amazon Web Services in the United States (us-east-2).
- Vercel — application hosting, delivery, and request logs. United States.
- Resend — transactional email delivery only. United States.
- Cloudflare — DNS for our domains. Cloudflare resolves our names; it does not sit in front of the application and does not receive personal data in that role.
There is no analytics vendor, no advertising network, no session-replay tool and no AI provider in the request path. If we add a payment processor — and we will, when billing launches — this list is updated before the vendor is switched on, not after.
If we are ever acquired or merge, personal data may transfer as part of that transaction. We will say so before it happens.
One separation worth stating plainly: an operator's data is not visible to any other operator. That boundary is enforced by row-level security inside the database rather than by application code, and it is covered by an automated test suite that tries to cross it and fails.
6Where it lives and how it is protected
Data is stored in the United States. Traffic is encrypted in transit using TLS, and data is encrypted at rest by our hosting providers. Tow photographs sit in a private bucket and are reachable only through short-lived signed links.
Authorization is decided in the database, not in application code: staff see only their own organization's records, staff scoped to particular properties see only those, and a resident sees only their own permits and unit. We maintain reasonable administrative, technical and physical safeguards appropriate to the volume and nature of the data, as §541.101(a)(2) requires, and we test the boundaries between accounts rather than assuming them.
NO SYSTEM IS PERFECTLY SECURE AND WE DO NOT CLAIM OTHERWISE. WE DO NOT REPRESENT THAT THE SERVICE IS IMPENETRABLE, THAT DATA CANNOT BE BREACHED, OR THAT SECURITY IS GUARANTEED.
If a breach affects personal data we hold, we will notify the affected Customer without undue delay so they can meet their own obligations, including those under Tex. Bus. & Com. Code ch. 521. Where we are the controller of the affected data, we will notify affected individuals and, where the thresholds in ch. 521 are met, the Texas Attorney General.
7How long we keep it
- Staff accounts, resident accounts, permits, properties and units — for as long as the Customer's subscription is active. On termination we keep the Customer's data for 30 days so it can be exported, then delete it.
- Plate check records — 24 months, after which they are deleted automatically by a scheduled job. This is enforced in the database, not by anyone remembering to do it. One exception, and we would rather name it than let you discover it: a plate check that a tow record points back to is kept for as long as that tow record is, because severing a tow from the check that preceded it would leave the tow standing alone with nothing to corroborate it. That serves nobody, and least of all the person disputing the tow. Every other plate check goes at 24 months.
- Rate-limiting counters — 7 days, deleted automatically.
- Tow records, their amendments and their photographs — seven years. These are evidence. A person whose vehicle was towed may bring a claim long after the fact, and both the operator and the vehicle owner are better served by the record still existing. Section 9 explains why this limits deletion.
- Demo requests and other enquiries — kept as ordinary business correspondence while the conversation is live and for a reasonable period afterwards. Ask us and we will delete yours; there is nothing that requires us to keep it.
- Agreement acceptance records — for as long as the agreement could still be disputed, and no less than four years after the account closes.
- Backups — deleted data may persist in encrypted backups for a limited period before those backups age out.
8Your rights
We honour the rights below for everyone whose data we hold, whether or not the law of your state currently reaches a company our size. Depending on where you live you may hold them under the Texas Data Privacy and Security Act, the California Consumer Privacy Act as amended, or a comparable law elsewhere.
- To know whether we process personal data about you.
- To access it, and to obtain a copy in a portable, machine-readable format where we processed it electronically.
- To correct inaccuracies, taking into account the nature of the data and the purpose it is held for.
- To delete personal data provided by or obtained about you, subject to section 9.
- To opt out of sale, targeted advertising, or profiling with legal effects — none of which we do, so there is nothing here to exercise.
- Not to be discriminated against for exercising any of these rights. We will not deny you the Service, charge a different price, or give you a lower quality of service because you asked.
9How to exercise them, and how to appeal
The methods required by §541.102(a)(3), (a)(6) and §541.055.
Making a request
Email Matthew.Maldonado@innovationsapplab.com with the word "Privacy" in the subject line, or write to us at the postal address available on request. You do not need to create an account to make a request, and we will not require you to.
Tell us what you want and enough to find you — the property, the unit, or the plate.
If you are a resident of a property, you can delete your own account at any time from your parking portal — open it, scroll to the bottom and choose "Delete my account". That removes your login, your name, your email address, the vehicles you registered and your link to the unit, immediately and without asking anyone's permission. Section 10 explains the one thing it does not remove.
For anything else — a copy of your information, a correction, or a question about a record you cannot see — contact the property or its towing operator first. They control your records; we hold them on that operator's behalf. If you do not know who to contact, or they do not respond, write to us and we will identify the right party, pass your request on, and tell you we have done so. Where we can act ourselves without countermanding the Customer's instructions, we will.
If you are a staff user of an operator or management company, write to us directly. We control those records.
What happens next
We may need to verify your identity before acting, and we will ask only for what is necessary. If we cannot authenticate a request through commercially reasonable effort we may decline it, and we will tell you why.
We respond without undue delay and within 45 days. We may extend once by a further 45 days where reasonably necessary, and we will tell you before the first period is up if we need to.
Appealing a refusal
If we refuse a request, we will tell you why, and you may appeal.
To appeal, reply to our refusal, or email the address above with "Privacy Appeal" in the subject line, within a reasonable period after you receive our decision. We will review it and respond in writing within 60 days of receiving the appeal, explaining the reasons for the decision either way. That deadline is §541.053's, and we treat it as a ceiling rather than a target.
If we deny your appeal, you may submit a complaint to the Texas Attorney General through the online mechanism the Attorney General maintains under §541.152. The Attorney General's page for this Act is at texasattorneygeneral.gov, and the complaint portal itself is at consumerprotection.texasattorneygeneral.gov. Complaints may also be sent to the Office of the Attorney General, Consumer Protection Division, PO Box 12548, Austin, Texas 78711-2548.
We will give you that information in the denial itself, because §541.053 requires it — not only if you think to ask for it.
10The limits on deletion, stated honestly
Two limits, and we would rather set them out here than surprise you with them.
We will not delete a tow record on request. A tow record documents an action already taken against a vehicle. It is retained to establish or defend legal claims — the vehicle owner's claim as much as the operator's — and deleting it would destroy the only contemporaneous account of what happened. That is our position, and we would rather argue it in the open than bury it: when a deletion request reaches a tow record we will say so, say why, and tell you how to appeal.
What we will do instead: if a tow record contains a factual error, tell us and we will append a correction to it. The record is built to be amended that way rather than rewritten, so the original and the correction both survive.
When we do delete a resident's records, what goes is the resident's account and identity: the account itself, the name, the email address, the permits, the vehicles registered under them, and the link to a unit. What remains is the tow record, which keeps the plate and the vehicle description because those are the facts of the event.
We will also keep what we must to comply with law, and the minimum needed to remember that you asked us to delete something, so we do not silently re-import you. That last allowance is §541.052(f), it is deliberately small, and we use it for nothing else.
11Cookies
We use only the cookies needed to keep you signed in and to keep signing in secure. There are no advertising cookies, no third-party analytics that follow you to other sites, and no consent banner — because there is nothing here to consent to.
12Changes
If we change this notice we will update the effective date and the version at the top. For changes that materially reduce your rights or expand how we use personal data, we will give Customers at least 30 days' notice by email before the change takes effect, and we will ask staff users to accept the new version when they next sign in.
Every published version of this notice is retained with its hash, so it is always possible to establish what it said on a given date.